#ifdef HAVE_CONFIG_H
# include <config.h>
#endif
#include <grp.h>
#include <stdarg.h>
#include <stdlib.h>
#include <string.h>
#include <sys/time.h>
#include <time.h>
#include <pwd.h>
#include <unistd.h>
#include "logger.h"
#include "util_helper.h"
#ifdef __linux__
extern char **environ;
#endif
static char **argv_buffer = NULL;
static size_t argv_size = 0;
#ifdef sun
#include <priv.h>
void
drop_privileges(int keep_auxgroups)
{
priv_set_t *pPrivSet;
if ((pPrivSet = priv_allocset()) == NULL) {
return;
}
priv_basicset(pPrivSet);
(void) priv_delset(pPrivSet, PRIV_FILE_LINK_ANY);
(void) priv_delset(pPrivSet, PRIV_PROC_INFO);
(void) priv_delset(pPrivSet, PRIV_PROC_SESSION);
(void) priv_addset(pPrivSet, PRIV_SYS_CONFIG);
(void) priv_addset(pPrivSet, PRIV_PROC_AUDIT);
(void) setppriv(PRIV_SET, PRIV_PERMITTED, pPrivSet);
(void) setppriv(PRIV_SET, PRIV_LIMIT, pPrivSet);
priv_freeset(pPrivSet);
}
#else
void
drop_privileges (int keep_auxgroups)
{
struct passwd *pw = NULL;
struct group *gr = NULL;
pw = getpwnam (HAL_USER);
if (!pw) {
HAL_DEBUG (("drop_privileges: user " HAL_USER " does not exist"));
exit (-1);
}
gr = getgrnam (HAL_GROUP);
if (!gr) {
HAL_DEBUG (("drop_privileges: group " HAL_GROUP " does not exist"));
exit (-1);
}
if (keep_auxgroups) {
if (initgroups (HAL_USER, gr->gr_gid)) {
HAL_DEBUG(("drop_privileges: could not initialize groups"));
exit (-1);
}
}
if (setgid (gr->gr_gid)) {
HAL_DEBUG (("drop_privileges: could not set group id"));
exit (-1);
}
if (setuid (pw->pw_uid)) {
HAL_DEBUG (("drop_privileges: could not set user id"));
exit (-1);
}
}
#endif
void
hal_set_proc_title_init (int argc, char *argv[])
{
#ifdef __linux__
unsigned int i;
char **new_environ, *endptr;
for (i = 0; environ[i] != NULL; i++)
;
endptr = i ? environ[i-1] + strlen (environ[i-1]) : argv[argc-1] + strlen (argv[argc-1]);
argv_buffer = argv;
argv_size = endptr - argv_buffer[0];
new_environ = malloc (sizeof(char*) * (i + 1));
for (i = 0; environ[i] != NULL; i++)
new_environ[i] = strdup (environ[i]);
new_environ[i] = NULL;
environ = new_environ;
#endif
}
void
hal_set_proc_title (const char *format, ...)
{
#ifdef __linux__
size_t len;
va_list ap;
if (argv_buffer == NULL)
goto out;
va_start (ap, format);
vsnprintf (argv_buffer[0], argv_size, format, ap);
va_end (ap);
len = strlen (argv_buffer[0]);
memset (argv_buffer[0] + len, 0, argv_size - len);
argv_buffer[1] = NULL;
out:
;
#endif
}